It's a kick ass combination for dump memory segments, unpack EXE files and restore import table of them.
Big thank to Christoph Gabler, MackT, Ms-Rem,snaker
Greets to LibX, Yoda, Cyber Daemon, decx, xor37h, Dr.Golova
and fuck to all encryptor's authors...
Future plans: Relocations restorer, Resource fixer, DLL support,
DRx tracer, PE64 support
Release history:
1.1 (06.03.2006) - Add: Safe dump procedure
- Add: Ring0 dumper
- Add: Protect MGD process
- Add: Kernel modules can be dumped
- !!!: -R changed to -D
- Fix: Dumped file erased after unsuccess IAT restore
- Fix: Commands A, C - sometimes dumped files was bad
- Fix: Removed LordPE requirement, bugs during dump
1.0 (25.02.2006) - Initial release
知道的人知道这个是什么好东西,ring0的dumper.
就是介绍上够猛,粗口都用上了
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课